Complete list of current Q & A>> Download Juniper Security, Professional (JN0-636) – Quiz 1 / 15 Category: Juniper Security, Professional (JN0-636) Which statement is true about persistent NAT types? A. The target-host-port parameter cannot be used with IPv4 addresses in NAT46. B. The target-host parameter cannot be used with IPv6 addressee in NAT64. C. The target-host parameter cannot be used with IPv4 addresses in NAT46 D. The target-host-port parameter cannot be used with IPv6 addresses in NAT64 2 / 15 Category: Juniper Security, Professional (JN0-636) In Juniper ATP Cloud, what are two different actions available in a threat prevention policy to dealwith an infected host? (Choose two.) A. Send a custom message B. Close the connection. C. Drop the connection silently. D. Quarantine the host. 3 / 15 Category: Juniper Security, Professional (JN0-636) You are asked to detect domain generation algorithms Which two steps will accomplish this goal on an SRX Series firewall? (Choose two.) A. Define an advanced-anti-malware policy under [edit services]. B. Attach the security-metadata-streaming policy to a security C. Define a security-metadata-streaming policy under [edit] D. Attach the advanced-anti-malware policy to a security policy. 4 / 15 Category: Juniper Security, Professional (JN0-636) You are connecting two remote sites to your corporate headquarters site. You must ensure that alltraffic is secured and sent directly between sites In this scenario, which VPN should be used? A. IPsec ADVPN B. hub-and-spoke IPsec VPN C. Layer 2 VPN D. full mesh Layer 3 VPN with EBGP 5 / 15 Category: Juniper Security, Professional (JN0-636) You are asked to deploy filter-based forwarding on your SRX Series device for incoming traffic sourced from the 10.10 100 0 network in this scenario, which three statements are correct? (Choose three.) A. You must create a forwarding-type routing instance. B. You must create and apply a firewall filter that matches on the source address 10.10.100.0 andthen sends this traffic to your routing C. You must create and apply a firewall filter that matches on the destination address 10 10.100.0and then sends this traffic to your routing instance. D. You must create a RIB group that adds interface routes to your routing instance. E. You must create a VRF-type routing instance. 6 / 15 Category: Juniper Security, Professional (JN0-636) Which three type of peer devices are supported for Cos-Based IPsec VPN? A. High-end SRX Series device B. cSRX C. vSRX D. Branch-end SRX Series devics 7 / 15 Category: Juniper Security, Professional (JN0-636) You have the NAT rule, shown in the exhibit, applied to allow communication across an IPsec tunnelbetween your two sites with identical networks. Which statement is correct in this scenario? A. The NAT rule with translate the source and destination addresses. B. The NAT rule will only translate two addresses at a time. C. The NAT rule in applied to the N/A routing instance. D. 10 packets have been processed by the NAT rule. 8 / 15 Category: Juniper Security, Professional (JN0-636) You are connecting two remote sites to your corporate headquarters site; you must ensure that alltraffic is secured and only uses a single Phase 2 SA for both sites. In this scenario, which VPN should be used? A. An IPsec group VPN with the corporate firewall acting as the hub device. B. Full mesh IPsec VPNs with tunnels between all sites. C. A hub-and-spoke IPsec VPN with the corporate firewall acting as the hub device. D. A full mesh Layer 3 VPN with the corporate firewall acting as the hub device. 9 / 15 Category: Juniper Security, Professional (JN0-636) You are asked to configure a security policy on the SRX Series device. After committing the policy, youreceive the œPolicy is out of sync between CK and PFE <SPU-name(s)>. error. Which command would be used to solve the problem? A. request security polices resync B. request service-deployment C. request security polices check D. restart security- intelligence 10 / 15 Category: Juniper Security, Professional (JN0-636) What would be a cause of this problem? A. The collector must have a minimum of two interfaces. B. The collector must have a minimum of three interfaces. C. The collector must have a minimum of five interfaces. D. The collector must have a minimum of four interfaces. 11 / 15 Category: Juniper Security, Professional (JN0-636) You opened a support ticket with JTAC for your Juniper ATP appliance. JTAC asks you to set up access to the device using the reverse SSH connection.Which three setting must be configured to satisfy this request? (Choose three.) A. Enable JTAC remote access B. Create a temporary root account. C. Enable a JATP support account. D. Create a temporary admin account. E. Enable remote support. 12 / 15 Category: Juniper Security, Professional (JN0-636) Your organization has multiple Active Directory domain to control user access. You must ensure that security polices are passing traffic based upon the users access rights. What would you use to assist your SRX series devices to accomplish this task? A. JIMS B. Junos Space C. JSA D. JATP Appliance 13 / 15 Category: Juniper Security, Professional (JN0-636) Which two log format types are supported by the JATP appliance? (Choose two.) A. YAML B. XML C. CSV D. YANG 14 / 15 Category: Juniper Security, Professional (JN0-636) You have designed the firewall filter shown in the exhibit to limit SSH control traffic to yours SRXSeries device without affecting other traffic. Which two statement are true in this scenario? (Choose two.) A. The filter should be applied as an output filter on the loopback interface. B. Applying the filter will achieve the desired result. C. Applying the filter will not achieve the desired result. D. The filter should be applied as an input filter on the loopback interface. 15 / 15 Category: Juniper Security, Professional (JN0-636) Which two additional configuration actions are necessary for the third-party feed shown in the exhibit to work properly? (Choose two.) A. You must create a dynamic address entry with the IP filter category and the ipfilter_office365value. B. You must create a dynamic address entry with the C&C category and the cc_offic365 value. C. You must apply the dynamic address entry in a security policy. You must apply the dynamic address entry in a security intelligence policy. Your score is 0% Restart quiz Send feedback